CVE-2025-13790

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

cpe:2.3:a:scada-lts:scada-lts:*:*:*:*:*:*:*:*

History

04 Dec 2025, 20:27

Type Values Removed Values Added
First Time Scada-lts scada-lts
Scada-lts
References () https://github.com/Xzzz111/exps/blob/main/archives/Scada-LTS-CSRF-1/report.md - () https://github.com/Xzzz111/exps/blob/main/archives/Scada-LTS-CSRF-1/report.md - Exploit, Third Party Advisory
References () https://github.com/Xzzz111/exps/blob/main/archives/Scada-LTS-CSRF-1/report.md#proof-of-concept - () https://github.com/Xzzz111/exps/blob/main/archives/Scada-LTS-CSRF-1/report.md#proof-of-concept - Exploit
References () https://vuldb.com/?ctiid.333794 - () https://vuldb.com/?ctiid.333794 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.333794 - () https://vuldb.com/?id.333794 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.690871 - () https://vuldb.com/?submit.690871 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:scada-lts:scada-lts:*:*:*:*:*:*:*:*

30 Nov 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-30 15:15

Updated : 2025-12-04 20:27


NVD link : CVE-2025-13790

Mitre link : CVE-2025-13790

CVE.ORG link : CVE-2025-13790


JSON object : View

Products Affected

scada-lts

  • scada-lts
CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-862

Missing Authorization